Description
Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
Published: 2026-09-08
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in the Windows DHCP Server that leads to remote code execution when an authorized attacker succeeds in exploiting the defect. The flaw allows untrusted code to run with the privileges of the DHCP service, giving the attacker the ability to take full control of the affected host. Because the attack requires only that the attacker be able to send packets to the DHCP server from the same subnet, it can be carried out against any host running the vulnerable service on a local network.

Affected Systems

Microsoft Windows 10 versions 1607 and 1809, and Windows Server 2012 through 2025 including Server Core installations are affected. The vulnerability is present in the DHCP service component distributed with these operating systems, so any machine that has the service enabled and has not applied the Microsoft update for this issue is at risk.

Risk and Exploitability

The CVSS score of 8 reflects a high severity, indicating that successful exploitation would give an attacker full control over the DHCP server host. While no EPSS score is published, the absence of an EPSS rating does not imply the flaw is benign; it simply indicates that no publicly reported exploitation has yet been observed, yet the vulnerability still poses a serious threat. The KEV status shows this issue is not listed in CISA’s Known Exploited Vulnerabilities catalog, but the high CVSS combined with the fact that an attacker only needs to send crafted packets from the same local subnet makes exploitation likely in environments where such network proximity is possible. Since the flaw exploits an authorized network attacker, typical protective measures such as network segmentation, strict DHCP traffic filtering, and disabling the DHCP role when unnecessary can effectively mitigate the risk.

Generated by OpenCVE AI on September 9, 2026 at 00:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest cumulative update for Windows Server that addresses CVE-2026-69876 and any applicable Windows 10 updates from Microsoft.
  • If the DHCP service is not required on the host, uninstall or disable the DHCP server role to remove the attack surface.
  • Configure network segmentation and firewall rules to block DHCP traffic from untrusted or unauthorized subnets, ensuring only legitimate DHCP clients can communicate with the service.

Generated by OpenCVE AI on September 9, 2026 at 00:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2012 (server Core Installation)
Microsoft windows Server 2012 R2
Microsoft windows Server 2012 R2 (server Core Installation)
Microsoft windows Server 2016 (server Core Installation)
Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2012 (server Core Installation)
Microsoft windows Server 2012 R2
Microsoft windows Server 2012 R2 (server Core Installation)
Microsoft windows Server 2016 (server Core Installation)
Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)

Thu, 10 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
Title Windows DHCP Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-415
CWE-416
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows Server 2012 Windows Server 2012 (server Core Installation) Windows Server 2012 R2 Windows Server 2012 R2 Windows Server 2012 R2 (server Core Installation) Windows Server 2016 Windows Server 2016 (server Core Installation) Windows Server 2019 Windows Server 2019 (server Core Installation) Windows Server 2022 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:36:35.438Z

Reserved: 2026-08-03T22:53:31.650Z

Link: CVE-2026-69876

cve-icon Vulnrichment

Updated: 2026-09-09T16:19:37.763Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:58.950

Modified: 2026-09-24T23:18:35.010

Link: CVE-2026-69876

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:55:38Z

Weaknesses